First published: Mon Apr 29 2019(Updated: )
IBM API Connect 2018.1 and 2018.4.1.2 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 155078.
Credit: psirt@us.ibm.com
Affected Software | Affected Version | How to fix |
---|---|---|
API Connect CLI Plugins | >=2018.1.0<=2018.4.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2018-2007 is considered to be high due to the potential for an attacker to decrypt sensitive information.
To fix CVE-2018-2007, upgrade IBM API Connect to a version that uses stronger cryptographic algorithms.
CVE-2018-2007 affects IBM API Connect versions 2018.1 and 2018.4.1.2.
CVE-2018-2007 is a cryptographic vulnerability that allows for the decryption of sensitive information.
Yes, CVE-2018-2007 can potentially be exploited remotely if the attacker can access the affected system.